Noida Institute of Engineering and Technology, Greater
Noida
AWS VIRTUAL INFRASTRUCTURE
Unit: 3
Subject Name
Mr. Rahul Sharma
Cloud Virtualization
Assistant Professor
Course Details CSE Department
B Tech 5th Sem
Mr. Rahul Sharma Cloud Virtualization Unit 3
1
04-12-2025
Brief Introduction of Faculty
Name : Mr. Rahul Sharma
Designation: Assistant Professor
Department: CSE
I, Rahul Sharma an Assistant Professor at Computer Science and Engineering
Department , Noida Institute of Engg and technology, Gr Noida. I have done
[Link],, and Master of Technology in Computer Science and Engineering from
MMMUT, Gorakhpur, UP
My area of research includes Data Science, IoT and Cloud.
Mr. Rahul Sharma Cloud
Virtualization Unit 3
04-12-2025 2
Evaluation Scheme
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 3
Subject Syllabus
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 4
Subject Syllabus
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 5
Course Objective
• The course intends to introduce students to the fundamentals of developing
application on Cloud, specifically public clouds such as AWS, AZURE and Google.
• To provide understanding of the concept of cloud and virtualization.
• To impart learning on virtualization architecture.
• To provide insights on cloud storage and migration solutions.
• To develop understanding of the cloud security and virtualized solutions.
Mr. Rahul Sharma Cloud Virtualization Unit 3
04-12-2025 6
Course Outcome
After completion of this course students will be able to:
CO1 Understand the fundamentals and core of Virtualization
CO2 Create Virtual Machines (VM) and compute instances of various configurations.
CO3 Develop virtual private connections using various network virtualization
techniques
CO4 Understand and analyze virtual storage solutions for various usage.
CO5 Analyze cloud security solutions and monitoring tools to evaluate the performance
of cloud resources.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 7
Program Outcome
Engineering Graduates will be able to Understand:
1. Engineering knowledge
2. Problem analysis
3. Design/development of solutions
4. Conduct investigations of complex problem
5. Modern tool usage
6. The engineer and society
7. Environment and sustainability
8. Ethics
9. Individual and team work
10. Communication
11. Project management and finance
12. Life-long learning
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 8
CO-PO Mapping
Sr. No Course PO1 PO2 PO3 PO4 PO5 PO6 PO7 PO8 PO9 PO10 PO11 PO12
Outcome
1 CO 1 3 2 1 1 1
2 CO 2 1 1 3 3 1 1
3 CO 3 1 3 3 1 1 1
4 CO 4 2 2 2 2 1 2 1
5 CO 5 2 3 3 3 3 2 2 1 1
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 9
Program Specific Outcome (PSO)
PSO1: The ability to identify, analyze real world problems and design their ethical
solutions using artificial intelligence, robotics, virtual/augmented reality, data
analytics, block chain technology and cloud computing.
PSO2: The ability to design and develop the hardware sensor devices and related
interfacing software systems for solving complex engineering problems.
PSO 3: The ability to understand inter disciplinary computing techniques and to
apply them in the design of advanced computing.
PSO 4: The ability to conduct investigation of complex problem with the help of
technical, managerial, leadership qualities, and modern engineering tools provided
by industry sponsored laboratories.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 10
CO- PSO Mapping
PSO1 PSO2 PSO3 PSO4
CO1 3 1 3 1
CO2 3 2 3
CO3 2 3 2 3
CO4 2 1 1 3
CO5 2 1 2
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 11
CO-PO and PSO Mapping
S. No. Program Outcomes (PO) PO Description
Apply the knowledge of mathematics, science,
PO1 engineering fundamentals and an engineering
1 (Engineering Knowledge) specialization to the solution of complex engineering
problems.
Identify, formulate, review research literature, and
analyze complex engineering problems reaching
PO2
substantiated conclusions using first principles of
2 (Problem Analysis)
mathematics, natural sciences and engineering
sciences.
Design solutions for complex engineering problems
PO3 and design system components or processes that meet
(Design/Development of the specified needs with appropriate considerations for
3
solutions) the public health and safety, and the cultural, societal
and environmental considerations.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 12
CO-PO and PSO Mapping
PO4
Use research based knowledge and research methods
(Conduct
including design of experiments, analysis and interpretation
Investigations of
4 of data and synthesis of the information to provide valid
complex
conclusions.
problems)
Create, select and apply appropriate techniques, resources
PO5
and modern engineering and IT tools including prediction
(Modern tool
5 and modeling to complex engineering activities with an
usage)
understanding of the limitations.
Apply reasoning informed by the contextual knowledge to
PO6
assess societal, health, safety, legal and cultural issues and
(The engineer
6 consequent responsibilities relevant to the professional
and society)
engineering practice.
PO7 Understand the impact of the professional engineering
(Environment solutions in societal and environmental contexts,
7
and demonstrate the knowledge of, and need for sustainable
sustainability) development.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 13
CO-PO and PSO Mapping
Apply the ethical principles and commit to
PO8
8 professional ethics, responsibilities, and norms of
(Ethics)
engineering practice.
PO9 Function effectively as an individual, and as a
9 (Individual and member or leader in diverse teams and
team work) multidisciplinary settings.
Communicates effectively on complex engineering
activities with the engineering community and with
PO10
society such as being able to comprehend and write
10 (Communication
effective reports and design documentation, make
)
effective presentations and give and receive clear
instructions.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3
14
CO-PO and PSO Mapping
Demonstrate knowledge and understanding of the
PO11 engineering and management principles and apply
11 (Project management these to one’s own work, as a member and leader in a
and finance) team, to manage projects and in multidisciplinary
environments.
Recognize the need for, and have the preparation and
PO12 ability to engage in independent and life-long
12
(Life-long learning) learning in the broadest context of technological
change.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3
15
Program Educational Objective (PEO)
PEO 1: To have an excellent scientific and engineering breadth so as to comprehend,
analyze, design and provide sustainable solutions for real life problems using state of the art
technologies.
PEO 2: To have a successful career in industries, to pursue higher studies or to support
entrepreneurial endeavors and to face the global challenges.
PEO 3: To have an effective communication skills, professional attitude, ethical values and
a desire to learn specific knowledge in emerging trends, technologies for research,
innovation and product development and contribution to society.
PEO 4: To have life-long learning for up-skilling and re-skilling for successful professional
career as engineer, scientist, entrepreneur and bureaucrat for betterment of society.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 16
CO- PEO Mapping
PEO1 PEO2 PEO3 PEO4
CO1 1 1 1 2
CO2 1 1 1 2
CO3 1 1 3 2
CO4 3 1 1 2
CO5 3 1 1 2
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 17
Result Analysis
Result Not Available
(New Subject)
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 18
End Semester Question Paper Template
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 19
End Semester Question Paper Template
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 20
End Semester Question Paper Template
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 21
End Semester Question Paper Template
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 22
Prerequisite and Recap
Adequate knowledge of Basics of Cloud Computing and Its architecture covered
through courses prior to this semester.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 23
Unit Content
Building virtual infrastructure with servers and networking
Using Virtual Servers:EC2
Programming your Infrastructure: The Command-Line Interface, SDKs, Cloud
Formation
Automating Deployment: Cloud Formation, Elastic Beanstalk, OPSWORKS
Securing your System: IAM, Security Groups, VPC
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 24
Unit Objective
To make the students understand Building virtual infrastructure with servers and
networking
To understand Using Virtual Servers:EC2
To understand Programming your Infrastructure: The Command-Line Interface,
SDKs, Cloud Formation
To understand Automating Deployment: Cloud Formation, Elastic Beanstalk,
OPSWORKS
To understand Securing your System: IAM, Security Groups, VPC
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 25
Building virtual infrastructure with servers and
networking
Building virtual infrastructure involves using a hypervisor on
physical servers to create multiple virtual machines (VMs) and
software-defined networks (SDNs) that abstract and manage
network resources.
This process includes installing virtualization software,
configuring the hypervisor and virtual switches, and then
creating and deploying VMs with operating systems.
The goal is to create a flexible, efficient environment that
allows for easy allocation of resources, scalability, and
simplified management of servers and networks
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 26
Building virtual infrastructure with servers and
networking
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 27
Key Components of Virtual Infrastructure
Physical Hosts: The underlying physical servers that provide the
hardware resources (CPU, RAM, storage) for the virtual machines.
Hypervisor: Software layer that runs on the physical hosts and is
responsible for creating, managing, and allocating resources to
multiple virtual machines.
Virtual Machines (VMs): Software-based representations of
physical servers that run their own operating systems and
applications.
Virtual Network: A logical network that is created on top of
physical network hardware, allowing VMs to communicate with
each other and with the outside world.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 28
Steps to Build Virtual Infrastructure
1. Choose Virtualization Software: Select virtualization software like
VMware, Microsoft Hyper-V, or Proxmox to manage your virtual
environment.
2. Install the Hypervisor: Install the chosen hypervisor software on your
physical servers.
3. Configure Virtual Switches: Create and configure virtual switches to
manage network traffic between your VMs and the physical network.
4. Create Virtual Machines: Use the hypervisor's management interface to
create new virtual machines, allocating resources like CPU, memory, and
disk space.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 29
Steps to Build Virtual Infrastructure
5. Install Operating Systems: Install operating systems on the
newly created VMs, pointing them to OS installation media (ISOs).
6. Connect VMs to Networks: Configure the virtual network
adapters of your VMs to connect to the appropriate virtual switches.
7. Manage and Automate: Utilize management tools to monitor
resource allocation, migrate VMs, and automate routine tasks,
ensuring efficiency and smooth operations.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 30
Benefits of Virtualization
• Efficient Resource Utilization: Maximizes the use of physical
server resources by running multiple workloads on a single
machine.
• Scalability and Flexibility: Easily scale up or down resources for
applications as needs change, and quickly deploy new VMs.
• Cost Savings: Reduces hardware costs, energy consumption, and
physical space requirements.
• Improved Disaster Recovery: Enables features like VM
migration and data recovery to ensure business continuity.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 31
Elastic Compute Cloud
• EC2 stands for Amazon Elastic Compute Cloud and is a web service
from Amazon Web Services (AWS) that provides resizable virtual
computers (instances) in the cloud for running applications.
• Key benefits include scalability, cost-effectiveness through a pay-as-
you-go model, and the ability to deploy applications for various
workloads, from simple websites to complex machine learning
models
• It allows users to rent computing capacity, choosing from various
CPU, memory, and storage configurations to match their specific
needs, without managing physical hardware.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 32
Elastic Compute Cloud
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 33
Elastic Compute Cloud
1. Login to AWS: Sign in to your AWS account and navigate to the EC2
console.
2. Launch an Instance: Choose your desired instance type, operating
system, and configure the memory, storage, and other resources.
3. Deploy Applications: Once the virtual machine is running, you can
install and run your applications, just as you would on a physical server.
4. Scale as Needed: Use tools like Auto Scaling to automatically adjust
the number of instances based on real-time traffic and demand, or
manually resize instances as your needs change.
5. Stop When Done: You can stop or terminate your instances when
they are no longer needed, ensuring you only pay for the time you use
the compute capacity.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 34
Using virtual servers: EC2
Typical use cases for a virtual server are as follows:
Hosting a web application
Executing enterprise applications
Transforming or analyzing data
Monitoring and debugging a virtual server
If you need to find the reason for an error or misbehavior of an application, it’s
important to have access to tools that can help with monitoring and debugging. AWS
provides tools that let you monitor and debug your virtual servers. One approach is to
examine the virtual server’s logs.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 35
Using virtual servers: EC2
Showing logs from a virtual server
If you need to find out what your virtual server was doing during and after startup,
there’s a simple solution. AWS allows you to show the server’s logs with the help of the
Management Console (the web interface you use to start and stop virtual servers).
Monitoring the load of a virtual server
AWS can help you answer another question: is your virtual server close to its maximum
capacity?
Follow these steps to open the server’s metrics:
[Link] the EC2 service from the main navigation and select Instances from the
submenu.
[Link] the running virtual server by clicking the row in the table.
[Link] the Monitoring tab at lower right.
[Link] the Network In chart to dive into the details.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 36
Using virtual servers: EC2
Shutting down a virtual server
To avoid incurring charges, you should always turn off unused virtual servers. You can
use the following four actions to control a virtual server’s state:
Start—You can always start a stopped virtual server. If you want to create a
completely new server, you’ll need to launch a virtual server.
Stop—You can always stop a running virtual server. A stopped virtual server isn’t
billed and can be started later. If you’re using network-attached storage, your data
persists. A stopped virtual server doesn’t incur charges, except for attached
resources like network-attached storage.
Reboot—Have you tried turning it off and on again? If you need to reboot your
virtual server, this action will help. You won’t lose any data when rebooting a
virtual server, and all software is still installed after a reboot.
Terminate —Terminating a virtual server means deleting it. You can’t start a
virtual server that you’ve already terminated. The virtual server is deleted, together
with dependencies like network-attached storage and public and private IP
addresses. A terminated virtual server doesn’t incur charges.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 37
Using virtual servers: EC2
Changing the size of a virtual server
It’s always possible to change the size of a virtual server. This is an advantage of the
cloud and gives you the ability to scale vertically. If you need more computing power,
increase the size of the server. In this section, you’ll learn how to change the size of a
running virtual server. To begin, follow these steps to start a small virtual server:
[Link] the AWS Management Console and choose the EC2 service.
[Link] the wizard to launch a new virtual server by clicking the Launch Instance
button.
[Link] Ubuntu Server 14.04 LTS (HVM) as the AMI for your virtual server.
[Link] the instance type [Link].
[Link] Review and Launch to start the virtual server.
[Link] the summary for the new virtual server and click the Launch button.
[Link] the option Choose an Existing Key Pair, select the key pair mykey, and click
Launch Instances.
[Link] to the overview of EC2 instances and wait for the new virtual server’s state to
switch to Running.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 38
Using virtual servers: EC2
Starting a virtual server in another data center
AWS offers data centers all over the world.
To achieve low latency for requests over the internet, it’s important to choose the
closest data center for the majority of your users.
Changing a data center is simple.
The Management Console always shows the current data center you’re working in,
on the right side of the main navigation.
So far, you’ve worked in the data center N. Virginia (US) called us-east-1.
To change the data center, click N. Virginia and select Sydney from the menu.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 39
Using virtual servers: EC2
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 40
Using virtual servers: EC2
Allocating a public IP address
You’ve already launched some virtual servers while reading this book. Each virtual
server was connected to a public IP address automatically.
But every time you launched or stopped a virtual server, the public IP address
changed. If you want to host an application under a fixed IP address, this won’t
work.
AWS offers a service called Elastic IP addresses for allocating fixed public IP
addresses.
You can allocate and associate a public IP address to a virtual web server with the
following steps:
1. Open the Management Console and go to the EC2 service.
[Link] Elastic IPs from the submenu. You’ll see an overview of public IP addresses,
as shown in figure.
[Link] a public IP address by clicking Allocate New Address.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 41
Using virtual servers: EC2
Now you can associate the public IP address with a virtual server of your choice:
[Link] your public IP address and choose Associate Address from the Actions menu.
A dialog similar to figure appears.
2. Enter your virtual server’s instance ID in the Instance field. Your web server is the
only virtual server running at the moment, so you can begin typing i- and use auto-
completion to choose the server ID.
[Link] Associate to finish the process.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 42
Using virtual servers: EC2
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 43
Using virtual servers: EC2
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 44
Using virtual servers: EC2
Adding an additional network interface to a virtual server
In addition to managing public IP addresses, you can control your virtual server’s
network interfaces.
It’s possible to add multiple network interfaces to a virtual server and control the
private and public IP addresses associated with those network interfaces.
You use an additional network interface to connect a second public IP address to
your web server.
Follow these steps to create an additional networking interface for your virtual server.
[Link] the Management Console and go to the EC2 service.
[Link] Network Interfaces from the submenu.
[Link] Create Network Interface. A dialog opens.
[Link] 2nd interface as the description.
[Link] your virtual server’s subnet as the subnet for the new networking interface.
[Link] Private IP Address empty.
[Link] the Security Groups that have webserver in their description.
[Link] Yes, Create.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 45
Using virtual servers: EC2
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 46
Using virtual servers: EC2
Optimizing costs for virtual servers
Usually you launch virtual servers on demand in the cloud to gain maximum
flexibility.
You can start and stop an on-demand instance whenever you like, and you’re billed
for every hour the instance (virtual server) is running.
If you want to save money, you have two options: spot instances or reserved
instances. Both help to reduce costs but decrease your flexibility.
With a spot instance, you bid for unused capacity in an AWS data center; the price
is based on supply and demand.
You can use reserved instances if you need a virtual server for a year or longer; you
agree to pay for the given time frame and receive a discount in advance.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 47
Using virtual servers: EC2
Reserve virtual servers
Reserving a virtual server means to commit to using a specific virtual server in a
specific data center.
You have to pay for a reserved virtual server whether it’s running or not. In return,
you benefit from a price reduction of up to 60%.
On AWS, you can choose one of the following options if you want to reserve a
virtual server:
No Upfront, 1-year term
Partial Upfront, 1-year or 3-year term
All Upfront, 1-year or 3-year term
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 48
Using virtual servers: EC2
Bidding on unused virtual servers
In addition to reserved virtual servers, there’s another option for reducing costs:
spot instances.
With a spot instance, you bid for unused capacity in the AWS cloud.
A spot market is a market where standardized products are traded for immediate
delivery.
The price of the products on the market depend on supply and demand.
On the AWS spot market, the traded products are virtual servers, and they’re
delivered by starting a virtual server.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 49
Daily Quiz
Briefly explain four actions to control a virtual Server.
Explain Reserve Virtual Server.
Write down the typical use cases for a virtual Server.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 50
Recap
You can choose an OS when starting a virtual server.
■ Using logs and metrics can help you to monitor and debug a virtual server.
■ Changing the size of your virtual server gives you the flexibility to change the
number of CPUs, memory, and storage.
■ You can start a virtual server in different regions, consisting of multiple data
centers, all over the world.
■ Allocating and associating a public IP address to your virtual server gives you the
flexibility to replace a virtual server without changing the public IP address.
■ You can save on costs by reserving virtual servers or bidding for unused capacity
on the virtual server spot market.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 51
Programming your infrastructure: the command line,
SDKs, and Cloud Formation
Imagine that you want to create room lighting as a service.
To switch off the light in a room with software, you need a hardware device like a
relay that can break the circuit.
This hardware device must have some kind of interface that lets you send it
commands like on and off via software.
With a relay and an interface, you can offer room lighting as a service.
This also applies to virtual server as a service.
If you want to start a virtual server via software, you need hardware that can handle
and fulfill your request.
AWS provides infrastructure that can be controlled via an interface
called an application programming interface (API).
You can control every part of AWS over the API.
Calling the API is possible with SDKs for most programming languages, the
command line, and more sophisticated tools.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 52
Programming your infrastructure: the command line,
SDKs, and Cloud Formation
Infrastructure as code
Infrastructure as code describes the idea of using a high-level
programming language to control IT systems.
In software development tools like automated tests, code
repositories, and build servers are increasing the quality of software
engineering.
If your infrastructure can be treated as code, you can apply the same
techniques to infrastructure code that you do to your application
code.
you will improve the quality of your infrastructure by using
automated tests, code repositories, and build servers.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 53
Programming your infrastructure: the command line,
SDKs, and Cloud Formation
Automation and the DevOps movement
DevOps (Development operations) is an approach driven by
software development to bring development and operations closer
together.
The goal is to deliver rapidly developed software to the customer
without a negative impact on quality.
Communication and collaboration between development and
operations are therefore necessary.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 54
Programming your infrastructure: the command line,
SDKs, and Cloud Formation
Using the command-line interface
The AWS command-line interface (CLI) is a convenient way to use
AWS from your command line.
It runs on Linux, Mac, and Windows and is written in Python.
It provides a unified interface for all AWS services.
Unless otherwise specified, the output is in JSON format.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 55
Programming your infrastructure: the command line,
SDKs, and Cloud Formation
Programming with the SDK
AWS offers software development kits (SDKs) for a number of programming
languages:
■ Android ■ [Link] (JavaScript)
■ Browsers (JavaScript) ■ PHP
■ iOS ■ Python
■ Java ■ Ruby
■ .NET ■ Go
An AWS SDK is a convenient way to make calls to the AWS API from
your favorite programming language. The SDK takes care of things like
authentication, retry on error, HTTPS communication, and JSON
(de)serialization. You’re free to choose the SDK for your favorite
language,.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 56
Programming your infrastructure: the command line,
SDKs, and Cloud Formation
Controlling virtual servers with SDK: nodecc
The Node Control Center for AWS (nodecc) is an advancement in
managing multiple temporary EC2 servers with a text UI written in
JavaScript. nodecc has the following features:
■ It can handle multiple servers.
■ It’s written in JavaScript and runs in [Link], so it’s portable across
platforms.
■ It uses a textual UI.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 57
Programming your infrastructure: the command line,
SDKs, and CloudFormation
Using a blueprint to start a virtual server
Earlier, we talked about JIML to introduce the concept of infrastructure as code.
Luckily, AWS already offers a tool that does much better than JIML: AWS
CloudFormation.
CloudFormation is based on templates, which up to now we’ve called blueprints.
A template is a description of your infrastructure in JSON that can be interpreted by
CloudFormation.
Descriptive means you tell CloudFormation how your infrastructure should look
and how it’s connected.
You aren’t telling CloudFormation what actions are needed to create that
infrastructure, and you don’t specify the sequence in which the actions need to be
executed.
Again, it’s all about dependencies—but CloudFormation offers you more benefits.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 58
Programming your infrastructure: the command line,
SDKs, and Cloud Formation
Anatomy of a Cloud Formation template
A basic Cloud Formation template is structured into five parts:
[Link] version—The latest template format version is 2010-09-09, and this is
currently the only valid value. Specify this; the default is the latest version, which
will cause problems if a new format version is introduced in the future.
[Link]—What is this template about?
[Link]—Parameters are used to customize a template with values: for example,
domain name, customer ID, and database password.
[Link]—A resource is the smallest block you can describe. Examples are a
virtual server, a load balancer, or an elastic IP address.
[Link]—An output is comparable to a parameter, but the other way around.
An output returns something from your template, such as the public name of
an EC2 server.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 59
Programming your infrastructure: the command line,
SDKs, and Cloud Formation
The benefits of Cloud Formation are as follows:
It’s a consistent way to describe infrastructure on AWS.
It can handle dependencies.
It’s replicable.
It’s customizable.
It’s updatable.
It minimizes human failure.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 60
Daily Quiz
Explain Infrastructure as code.
Define Automation and the DevOps Movement.
Briefly Explain Cloud formation Template.
Write down various benefits of Cloud formation.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 61
Recap
■ Use the command-line interface (CLI), one of the SDKs, or CloudFormation to
automate your infrastructure on AWS.
■ Infrastructure as code describes the approach to program the creation and
modification of your infrastructure including virtual servers, networking, storage, and
more.
■ You can use the CLI to automate complex processes in AWS with scripts (Bash
and PowerShell).
■ You can use SDKs for nine programming languages to embed AWS into your
applications and create applications like nodecc.
■ CloudFormation uses a descriptive approach in JSON: you only define the end
state of your infrastructure, and CloudFormation figures out how this state can
be achieved. The major parts of a CloudFormation template are parameters,
resources, and outputs.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 62
Automating Deployment: CloudFormation
Automating Deployment: CloudFormation – Key Points
[Link]-Based Setup
1. Use YAML or JSON templates to define what resources you need.
[Link]-Click Deployment
1. Launch complete infrastructure (servers, databases, networks) with a single
command.
[Link] Environments
1. Ensures the same setup every time for dev, test, or production.
[Link] Lifecycle Management
1. Create, update, or delete entire resource groups (called stacks) easily.
[Link] and Effort Saving
1. Avoids manual configuration; speeds up deployment and scaling.
[Link] Feature
1. Automatically reverts changes if something goes wrong during deployment.
Rahul Sharma BCSAI0520 and CV Unit
12/4/2025 63
3
Elastic Beanstalk
Elastic Beanstalk is an AWS service that helps you deploy and
manage web applications easily by automatically handling
infrastructure tasks like server setup, load balancing, scaling, and
monitoring.
Key Points:
Supports multiple programming languages like Java, Python, PHP,
[Link], etc.
Handles automatic scaling and load balancing without manual
setup.
Lets you focus on code, while AWS manages the backend.
Provides monitoring and health dashboards for your app.
Allows customization of underlying AWS resources if needed.
Dr Rahul Sharma BCSAI0520 and CV
12/4/2025 64
Unit 3
OPSWORKS
AWS OpsWorks is a configuration management service that uses Chef
and Puppet automation tools to help you configure, deploy, and
manage servers and applications on AWS or on-premises
infrastructure.
Key Points:
Based on Chef/Puppet – Uses industry-standard automation
platforms for server configuration.
Automates infrastructure tasks like installing software, configuring
servers, and managing updates.
Supports lifecycle management – You can define actions for server
start, stop, or reboot.
Works with EC2 and on-premises servers for hybrid setups.
Helps maintain consistency across environments (dev, test, prod).
Dr Rahul Sharma BCSAI0520 and CV
12/4/2025 65
Unit 3
Securing your System: IAM
IAM (Identity and Access Management)
Definition:
AWS IAM is a security service that helps you control who can access your AWS resources
and what actions they can perform. It allows you to manage users, groups, roles, and
permissions securely.
IAM – Key Points (Brief)
User and Group Management – Create and manage AWS users and group them for easier
permission control.
Fine-Grained Permissions – Control exactly what actions a user or group can perform.
IAM Roles – Assign permissions to AWS services or external users without using passwords.
Multi-Factor Authentication (MFA) – Adds extra security using OTP-based login.
Temporary Access – Provides limited-time access using temporary credentials.
Policy-Based Control – Uses JSON policy documents to define who can access what.
Follows Least Privilege Principle – Give only the minimum access required to perform a task.
Dr Rahul Sharma BCSAI0520 and CV
12/4/2025 66
Unit 3
Security Groups
Security Groups
Security Groups act as virtual firewalls for your AWS resources like EC2
instances. They control inbound and outbound traffic based on rules
you define (such as IP address, port number, and protocol).
Key Points (Brief)
Instance-Level Firewall – Applied to EC2 instances to control traffic.
Rule-Based Access – You define inbound and outbound rules (e.g., allow
port 22 for SSH).
Stateful – If inbound traffic is allowed, the return traffic is automatically
allowed.
Default Deny – All traffic is denied unless explicitly allowed.
No Deny Rules – You can only add allow rules, not deny rules.
Can Attach Multiple Groups – One instance can have more than one
security group.
Dr Rahul Sharma BCSAI0520 and CV
12/4/2025 67
Unit 3
VPC
What is VPC?
Imagine you're building your own private network inside AWS — like your personal data
center in the cloud. That’s what VPC is.
Easy Key Points:
Your Own Space – VPC gives you a private space to run your apps securely on AWS.
Control IPs – You decide what IP address range your machines will use.
Subnets – You can split your space into parts:
Public subnet (can access the internet)
Private subnet (hidden from the internet)
Internet Access – To let public subnet connect to the internet, you attach an Internet
Gateway (IGW).
NAT Gateway – Lets private machines access the internet without exposing them.
Security Rules – You add rules (like firewalls) using Security Groups and NACLs.
Dr Rahul Sharma BCSAI0520 and CV
12/4/2025 68
Unit 3
Daily Quiz
Explain about various components of Elastic Benstalk.
Briefly Explain about Components of Ops Works.
Write down the necessary steps to deploy a two layer application with the help of
Opsworks.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 69
Recap
■ It isn’t advisable to deploy applications to virtual servers manually because virtual
servers pop up more often in a dynamic cloud environment.
■ AWS offers different tools that can help you deploy applications onto virtual
servers. Using one of these tools prevents you from reinventing the wheel.
■ OpsWorks is good for deploying multilayer applications with the help of Chef.
■ Elastic Beanstalk is best suited for deploying common web applications.
■ CloudFormation gives you the most control when you’re deploying more complex
applications.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 70
Securing your system: IAM, security groups, and VPC
If security is a wall, you’ll need a lot of bricks to build that wall. In this focuses
on the four most important bricks to secure your systems on AWS:
Installing software updates—New security vulnerabilities are found in software
every day. Software vendors release updates to fix those vulnerabilities. It’s
your job to install those updates as quickly as possible after they’re released.
Otherwise, your system will be an easy victim for hackers.
Restricting access to your AWS account—This becomes even more important if you
aren’t the only one accessing your AWS account (if coworkers and scripts are
also accessing it). A script with a bug can easily terminate all your EC2 instances
instead of the one you intended. Granting least permissions is key to securing
your AWS resources from accidental or intended disastrous actions.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 71
Securing your system: IAM, security groups, and VPC
Controlling network traffic to and from your EC2 instances—You only want ports
to be accessible if they must be. If you run a web server, the only ports you need to
open to the outside world are port 80 for HTTP traffic and 443 for HTTPS traffic. Close
down all the other ports!
Creating a private network in AWS—You can create subnets that aren’t reachable
from the internet. And if they’re not reachable, nobody can access them.
Nobody? You’ll learn how you can get access to them while preventing others
from doing so.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 72
Securing your system: IAM, security groups, and VPC
Who’s responsible for security?
AWS is a shared-responsibility environment, meaning responsibility is shared
between AWS and you. AWS is responsible for the following:
Protecting the network through automated monitoring systems and robust
internet access to prevent Distributed Denial of Service (DDoS) attacks.
Performing background checks on employees who have access to sensitive areas.
Decommissioning storage devices by physically destroying them after end of life
Ensuring physical and environmental security of data centers, including fire
protection and security staff.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 73
Securing your system: IAM, security groups, and VPC
Keeping your software up to date
Not a week goes by without the release of important updates to fix security
vulnerabilities.
Sometimes your OS is affected; or software libraries like OpenSSL; or
environments like Java, Apache, and PHP; or applications like WordPress.
If a security update is released, you must install it quickly, because the exploit may
have been released with the update or because everyone can look at the source code
to reconstruct the vulnerability.
You should have a working plan for how to apply updates to all running servers as
quickly as possible.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 74
Securing your system: IAM, security groups, and VPC
Securing your AWS account
Securing your AWS account is critical.
If someone gets access to your AWS account, they can steal your data, destroy
everything (data, backups, servers), or steal your identity to do bad stuff.
Each AWS account comes with a root user.
You are using the root user when you use the Management Console; if you use the
CLI, you are using the mycli user that you created.
In addition to the root user, an AWS account is a basket for all the resources you
own: EC2 instances, CloudFormation stacks, IAM users, and so on.
To access your AWS account, an attacker must be able to authenticate with your
account.
There are three ways to do so: using the root user, using a normal user, or
authenticating as an AWS resource like an EC2 instance.
To authenticate as a (root) user, the attacker needs the password or the access key.
To authenticate as an AWS resource like an EC2 server, the attacker needs to send
API/CLI requests from that EC2 instance.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 75
Securing your system: IAM, security groups, and VPC
Roles for authentication of AWS resources
An IAM role can be used to authenticate AWS resources like virtual servers. You
can attach no roles, one role, or multiple roles to an EC2 instance.
Each AWS API request from an AWS resource (like an EC2 instance) will
authenticate with the roles attached.
If the AWS resource has one role or multiple roles attached, IAM will check all
policies attached to those roles to determine whether the request is allowed.
By default, EC2 instances have no role and therefore aren’t allowed to make any
calls to the AWS API.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 76
Securing your system: IAM, security groups, and VPC
Controlling network traffic to and from your virtual server
You only want traffic to enter or leave your EC2 instance that has to do so.
With a firewall, you can control ingoing (also called inbound or ingress) and
outgoing (also called outbound or egress) traffic.
If you run a web server, the only ports you need to open to the outside world are
port 80 for HTTP traffic and 443 for HTTPS traffic.
All other ports should be closed down. Only open ports that must be open, just as
you grant least permissions with IAM.
If you have a strict firewall, you shut down a lot of possible security holes.
You can also prevent the accidental sending of mail to customers from a test system
by not opening outgoing SMTP connections for test systems.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 77
Securing your system: IAM, security groups, and VPC
Creating a private network in the cloud: Virtual Private Cloud
(VPC)
By creating a Virtual Private Cloud (VPC), you get your own private network on
AWS.
Private means you can use the address ranges [Link]/8, [Link]/12, or
[Link]/16 to design a network that is not necessarily connected to the public
internet.
You can create subnets, route tables, access control lists (ACLs), and gateways to
the internet or a VPN endpoint.
A subnet allows you to separate concerns.
Another rule of thumb is that you should have at least two subnets: public and
private.
A public subnet has a route to the internet; a private subnet does not.
Your web servers should be in the public subnet, and your database resides
in the private subnet.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 78
Daily Quiz
Briefly explain about securing your AWS account.
Write down Four Most important bricks to secure your systems on AWS.
How to create a private network in the cloud.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 79
Weekly Assignment
Write down various benefits of Cloud formation.
Write down the necessary steps to deploy a two layer application with the help of
Opsworks.
Briefly explain about securing your AWS account.
Write down the typical use cases for a virtual Server.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 80
Youtube & NPTEL Video Links and Online Courses
Details
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
[Link]
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 81
MCQ s
[Link] is a software distribution model in which applications are hosted by a vendor or
service provider and made available to customers over a network, typically the Internet.
[Link] as a Service (PaaS)
[Link] as a Service (IaaS)
[Link] as a Service (SaaS).
[Link] of these
2. Amazon Web Services (AWS) is an example of
A. software as a service(saas)
B. infrastructure as aservice (iaas)
C. platform as a service(paas)
D. none of the mentioned
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 82
MCQ s
[Link] of the following statements about Google App Engine (GAE) is INCORRECT
[Link]'s a Platform as a Service (PaaS) model.
[Link] Scalability is built in with GAE. As a developer you don't need to worry
about application scalability
[Link] can decide on how many physical servers required for hosting your application.
[Link] applications deployed on GAE have the same security, privacy and data protection
policies as that of Google's applications. So, applications can take advantage of
reliability, performance and security of Google's infrastructure.
[Link] is a public cloud?
A.A cloud formation that can be seen across the globe
B.A cloud service that can only be accessed from a publicly shared computer
C.A multi-tenant cloud environment accessed over the internet
D.A cloud environment owned, operated and controlled by a public company
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 83
Old Question Papers
Not applicable.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 84
Old Question Papers
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 85
Old Question Papers
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 86
Expected Questions for University Exam
Briefly explain four actions to control a virtual Server.
Explain Reserve Virtual Server.
Write down the typical use cases for a virtual Server.
Explain Infrastructure as code.
Define Automation and the DevOps Movement.
Briefly Explain Cloud formation Template.
Write down various benefits of Cloud formation.
Explain about various components of Elastic Benstalk.
Briefly Explain about Components of Ops Works.
Write down the necessary steps to deploy a two layer application with the help of
Opsworks.
Briefly explain about securing your AWS account.
Write down Four Most important bricks to secure your systems on AWS.
How to create a private network in the cloud.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 87
Summary
AWS is a shared-responsibility environment in which security can be achieved
only if you and AWS work together. You’re responsible for securely configuring
your AWS resources and your software running on EC2 instances while AWS
protects buildings and host systems.
Keeping your software up to date is key and can be automated.
The Identity and Access Management (IAM) service provides everything
needed for authentication and authorization with the AWS API. Every request
you make to the AWS API goes through IAM to check whether the request is
allowed. IAM controls who can do what in your AWS account. Grant least
permissions to your users and roles to protect your AWS account.
A VPC is a private network in AWS where you have full control. With VPCs, you
can control routing, subnets, ACLs, and gateways to the internet or your company
network via VPN.
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 88
References
Textbooks:
1) Distributed and Cloud Computing: From Parallel Processing to the Internet of Things
Geoffrey C. Fox, Jack Dongarra, and Kai Hwang.
2) Amazon Web Services in Action , Michael Wittig and Andreas Wittig
Reference Books:
1) ‘Cloud Computing’ by Shailendra Singh ; Oxford higher education 2022
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 89
References
04-12-2025 Mr. Rahul Sharma Cloud Virtualization Unit 3 90